> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/pt-br/active-directory/kerberos/general-kerberos-flow.md).

# Fluxo geral do Kerberos

### Etapa 1 — AS-REQ

Quando um usuário faz login, seu cliente envia uma consulta ao KDC:

```bash
AS-REQ
```

Essa consulta corresponde à consulta inicial de autenticação.

### Etapa 2 — AS-REP

Se a autenticação for válida, o KDC retorna uma resposta:

```bash
AS-REP
```

Essa resposta contém notavelmente um **TGT** , ou **Ticket de concessão de ticket**.

O TGT pode ser visto como um ticket geral que permite consultar tickets de serviço.

### Etapa 3 - TGS-REQ

Quando o usuário quer acessar um recurso, por exemplo um compartilhamento de rede, ele apresenta seu TGT ao KDC.

O cliente então envia:

```bash
TGS-REQ
```

Essa solicitação consulta um ticket para um serviço específico.

### Etapa 4 — TGS-REP

O KDC verifica o TGT e retorna um ticket de serviço:

```bash
TGS-REP
```

Esse ticket é específico para o serviço solicitado.

### Etapa 5 — Acesso ao recurso

O cliente apresenta o ticket de serviço ao servidor de destino.

Por exemplo, para acessar:

```bash
//WS01/C$
```

O cliente envia um ticket de serviço ao servidor `WS01`.

Se o ticket for válido, mas o usuário não tiver as permissões necessárias no compartilhamento, a autenticação pode ser bem-sucedida, mas o acesso SMB será negado.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/pt-br/active-directory/kerberos/general-kerberos-flow.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
